Service family

Sovereign AI and security

Some data must not leave your organization. And an exposed AI system must be tested like any other application. These two services meet both requirements.

A sovereign AI stack, tested against attacks On your premises or in a Canadian cloud: applications, AI gateway, local model and an index of your documents, on infrastructure you control, with an audit log covering every layer. Penetration tests target the gateway with known attacks. An external model is called only if authorized, with filtered data. YOUR SITE OR A CANADIAN CLOUD Applicationsassistant, agents, integrations AI gatewaypermissions, routing, filtering Local modelopen model Indexyour documents Infrastructureservers you control Audit logcovers every layer Penetration testsknown attacks(OWASP LLM) External modelif authorized,filtered data
Sensitive data stays inside your perimeter, and protection is verified by testing, not assumed.

Private AI hosted on your premises

Who it's for

Organizations whose data must not leave their infrastructure: client files, health information, trade secrets, contracts.

Typical problem

“We'd like to use AI on our documents, but sending them to a vendor abroad is out of the question.”

What we do

  • Selection of open models suited to your uses and your hardware.
  • Installation on your servers, or in a Canadian cloud that you control.
  • Access gateway: authentication, permissions, routing, audit log.
  • Assistant for your documents that respects existing access rights.

Deliverables

  • Private AI platform, installed and documented.
  • Usable audit log.
  • Administration guide.
  • Knowledge transfer to your IT team.

AI systems security

Who it's for

Organizations that expose an AI assistant, agent or API to staff, customers or partners.

Typical problem

“Our assistant has been online for three months. We don't know whether someone could get it to reveal internal data.”

What we do

  • Architecture review against the OWASP Top 10 for LLM Applications: prompt injection, data leakage, overly permissive agents, etc.
  • Targeted penetration tests of your AI applications, only with written authorization and a signed scope.
  • Prioritized recommendations and support with fixes.
  • Retesting after remediation.

Deliverables

  • Test report, with findings ranked by severity.
  • Prioritized remediation plan.
  • Retest report.

Proof

L6 — Penetration testing our own AI applications, and NB-TECH SHIELD, our security framework applied to our own systems.

No test is performed without written authorization specifying the scope, dates, permitted methods and contact persons.

Let's talk about your situation

Every organization has its own systems, data and constraints. We always start by understanding your situation. Scope and investment are then proposed in writing.